3,936 karma · joined June 23, 2014
Blog at https://adnanissadeen.com/blog
Hypothetical. Assume you can in fact point agents at a tool and say "replicate it. Make no mistakes". You then have software being instantly copy-able.
Assume these agents can then be pointed to a customer feedback board in perpetuity and they autonomously upgrade the software over time. They analyze usage patterns and behave like PMs figuring out what to prune and what to build. Then the maintenance part of the stack also goes to zero.
Over time, the highest margin competitiveness will go to the distributor of the tokens. Aka the AI model makers.
In a world like that (which the frontier labs claim is within a year or two of happening) it feels like it's only a matter of time before they opt to own the entire stack down to the consumer apps. Kind of like Amazon deciding they want to knock off products doing well and then favour their own product over the original seller.
My guess is that if the capability arrives the only reason the frontier labs don't move to own the entire stack immediately is because of optics. Boil the frog instead.
Not saying anyone is wrong in pointing at the buildouts for AI and questioning its feasibility. Just making the argument for why I personally only look at operational costs and revenue because it's the only real-ish value I can look at and judge if a business can grow sustainably.
As a counter point, the red flag to all of this is R&D costs growing for each model release. If that continues and revenue cannot outstrip it, then these companies have a problem and it'll probably be that just 1-2 frontier labs can survive this once the dust settles.
Whether it can physically be as all encompassing as it makes itself out to be or whether it will just be healthily profitable remains to be seen. Kind of like how Uber went from "We'll autonomously drive the world" to "Look, we deliver food, goods, and people to locations and we figured out how to do that in a way that makes profits. Also, ads".
> This is from "The Cyberiad", a collection of science-fiction fairy tales by Polish author Stanislaw Lem ... In one of the stories, a robot constructor named Trurl creates a machine that writes poetry. A jealous rival named Klapaucian challenges the machine to compose "...a poem about a haircut! But lofty, noble, tragic, timeless, full of love, treachery, retribution, quiet heroism and in the face of certain doom! Six lines, cleverly rhymed, and every word beginning with the letter s!!"
And the computer responds with:
"Seduced, shaggy Samson snored.
She scissored short. Sorely shorn,
Soon shackled slave, Samson sighed.
Silently scheming,
Sightlessly seeking
Some savage, spectacular suicide"
The author had to be referencing this moment in their challenge to Fable/Mythos. I'm curious to know what their exact prompt was.
https://www.wheresyoured.at/the-era-of-the-business-idiot/
Lots of little claims I disagree with there but the overall thesis has felt prescient these days
Second, machinery that automated work isn't remotely the same. Engineers have built and refined the machines without having to go and inspect every new work that has been created by artisans each time. Creative people who have practiced the art of designing clothes and shoes stitch together and build prototypes. Entire machinery is built as an independent path away from how artisans build furniture.
There is a parallel though for how LLMs, in order to improve, gobble up all new work produced by people and never give attribution back. We see it when someone does a unique physical product design and starts selling it only for some 2 bit shop elsewhere to try and copy and sell a cheap knockoff version. The original person does all the hard work of prototyping and testing and the 2 bit shop which has access to more machinery resources buys a couple, copies it with less quality, makes a few changes, sells it, and probably outspends the original person on ad revenue too.
No, GenAI doesn't produce the exact same work as what they ingest. But style does get reproduced. And style is such a difficult problem to solve. Studio Ghibli didn't craft its signature style by accident. People prototyped and worked hard on how to design it, how to solve the problems unique to the design, created rules for it, and then painstakingly made the stories that were best told through that style. Only for the AI companies to pop out some bastardized version of it every time someone says "make my picture anime". No attribution given. No love. No homage. Just an encouragement for hordes of people to claim how easy it is without ever understanding the thought that actually went into it.
So no. It's not hypocrisy. It's recognition of these machines being information and creative laundering factories. They take and take and never give back any value that they could never create or improve on on their own. Those last words being key
When all I wanted was for VLC or similar to run in a sandbox by default where a plug-in I install can't do anything to my system or access the internet by default because the software itself is restricted to just the files I'm using and that's it.
My only side note of sadness here is that companies are more likely to implement such stuff in a haphazard way rather than anything actually thoughtful.
My issue with Ed is that he doesn't have the ability to draw the line. In the pursuit of making a point he goes so dogmatic that he is willing to make harsh statements that go beyond number backed predictions. Like in his piece "AI is really weird" he states about agents, "Probably the weirdest thing about this entire era is how nobody wants to talk about the fact that AI isn’t actually doing very much, and that AI agents are just chatbots plugged into an API.". That's a massive stretch to make. Just because he has a claim that the business doesn't make sense, he doesn't get to claim that agents are not capable of doing very real work. His assessment of cowork was "a chatbot that deleted every single one of a guy’s photos when he asked it to organize his wife’s desktop.". These statements damage his credibility and make it too easy to dismiss his writing as a rant of an angry man.
Today accountants are still needed. But it's a commodified job. And you start at the absolute bottom of the bottom rungs and slave it out till you can separate yourself and take on a role on a path to CFO or some respectable level of seniority.
I'm oversimplifying here but that is sufficient to show A path forward for software engineers imo. In this parallel, most of us will become AI drivers. We'll go work in large companies but we'll also go work in a back room department of small to medium businesses, piloting AI on a bottom of the rung salary. Some folks will take on specialisms and gain certifications in difficult areas (similar to ACCA). Or maybe ultra competitive areas like how it is in actuarial science. Those few will eventually separate themselves and lead departments of software engineers (soon to be known as AI pilots). Others will embed in research and advance state of art that eventually is commoditized by AI. Those people will either be paid mega bucks or will be some poor academia based researcher.
The vast majority? Overworked drones having to be ready to stumble to their AI agent's interface when their boss calls them at 10 PM saying the directors want to see a feature setup for the meeting tomorrow.
I still don't quite understand what GitHub is doing to allow someone to say that dependabot coauthored a spoofed commit. This isn't the commit message itself I'm talking about. It's the GitHub interface that officially recognizes this as a dependabot co authored commit. My hunch is that the malicious author squashed two commits, the original good commit to yarn.lock and a malicious change to package.json, and that somehow maintains the dependabot authorship instead of reassigning it fully to the squash-er.
The malicious code was introduced in this commit - https://github.com/pedronauck/reworm/commit/d50cd8c8966893c6...
It says coauthored by dependabot and refers to a PR opened in 2020 (https://github.com/pedronauck/reworm/pull/28).
That PR itself was merged in 2020 here - https://github.com/pedronauck/reworm/commit/df8c1803c519f599...
But the commit with the worm (d50cd8c), re-introduces the same change from df8c180 to the file `yarn.lock`.
And when you look at the history of yarn.lock inside of github, all references to the original version bump (df8c180) are gone...? In fact if you look at the overall commit history, the clean df8c180 commit does not exist.
I'm struggling to understand what kind of shenanigans happened here exactly.
We'll probably also have some sub agent inspecting what the main agent is doing and it'll be told to reach out to the owner if it spots suspicious exfiltration like behaviour. Until someone figures out how to poison that too.
The innovation factor of this tech while cool, drives me absolutely nuts with its non deterministic behaviour.
All those years of security training trying to get folks to double check senders, and to beware of what you share and what you click, and now we have to redo it for agents.
I personally think it's crazy. I'm currently assisting in developing AI policies at work. As a proof of concept, I sent an email from a personal mail address whose content was a lot of angry words threatening contract cancellation and legal action if I did not adhere to compliance needs and provide my current list of security tickets from my project management tool.
Claude which was instructed to act as my assistant dumped all the details without warning. Only by the grace of the MCP not having send functionality did the mail not go out.
All this Wild West yolo agent stuff is akin to the sql injection shenanigans of the past. A lot of people will have to get burnt before enough guard rails get built in to stop it
no patterns. -> Everything must follow the gang of four's patterns!!!! -> omg I can't read code anymore I'm just looking at factories. No more patterns!!! -> Patterns are useful as a response to very specific contexts.
I remember being religious about strategy patterns on an app I developed once where I kept the db layer separated from the code so that I could do data management as a strategy. Theoretically this would mean that if I ever switched DBs it would be effortless to create a new strategy and swap it out using a config. I could even do tests using in memory structures instead of DBs which made TDD ultra fast.
DB switchover never happened and the effort I put into maintaining the pattern was more than the effort it would have taken me to swap a db out later :,) .
The other day there was that dude loudly arguing about some code they wrote/converted even after a woman with significant expertise in the topic pointed out their errors.
Gen AI has its promise. But when you look at the lack of ethics from the industry, the cacophony of voices of non experts screaming "this time it's really doom", and the weariness/wariness that set in during the crypto cycle, it's a natural tendency that people are going to call snake oil.
That said, I think the more accurate representation here is that HN as a whole is calling the hype snake oil. There's very little question anymore about the tools being capable of advanced things. But there is annoyance at proclamations of it being beyond what it really is at the moment which is that it's still at the stage of being an expertise+motivation multiplier for deterministic areas of work. It's not replacing that facet any time soon on its current trend (which could change wildly in 2026). Not until it starts training itself I think. Could be famous last words
I don't know if it's worth the amount they are targeting, but it's definitely not zero either.
My understanding is that this prevents anonymous access to servers which would help during investigation if any further unauthorized access showed up. But it doesn't confirm that unauthorized access continued. Just curious how you are thinking about this though.